Governance Risk Compliance (GRC) Specialist
Hong Kong
Qube Research & Technologies
Qube Research & Technologies (QRT) is a global quantitative and systematic investment manager, operating in all liquid asset classes across the world. We are a technology and data driven group implementing a scientific approach to investing. Combining data, research, technology, and trading expertise has shaped our collaborative mindset, which enables us to solve the most complex challenges. QRT’s culture of innovation continuously drives our ambition to deliver high quality returns for our investors.
As a GRC Specialist at Qube Research & Technologies (QRT), you will be responsible for taking ownership of our governance, risk, and compliance (GRC) policies and processes. You will play a pivotal role in managing security and risk programs, ensuring that we meet internal business objectives. This position requires strong knowledge of GRC frameworks, exceptional communication skills, and a proactive approach to managing risk.
This role presents an exciting opportunity for a motivated cybersecurity professional to shape the organization’s cybersecurity governance, risk management, and compliance landscape while driving impactful improvements in security posture.
Your future role within QRT
Risk Assessment and Mitigation:
- Design and lead risk management program across the company
- Develop risk mitigation strategies and work with cross-functional teams to implement risk controls
- Monitor, assess, and report on the effectiveness of risk mitigation measures.
- Conduct control assessments, identify gaps, and implement improvements to reduce risk exposure.
Security Governance & Program:
- Develop, implement, and maintain GRC policies and procedures in alignment with industry best practices and regulatory requirements (e.g., ISO 27001, NIST)
- Drive policy governance. Regularly review and update policies to reflect changes in the business environment and evolving compliance standards
- Ensure compliance with internal policies, track exceptions, and explore alternative risk reduction measures when necessary
- Stay updated on regulatory requirements, monitor changes, and collaborate with relevant teams to maintain compliance
- Contribute to the security training and awareness programs to employees to promote a healthy, balanced security culture
- Continuously assess and improve the effectiveness of GRC processes and controls
- Stay updated on emerging trends, and best practices in GRC
- Support the development, automation, and maintenance of cybersecurity metrics to drive informed decision-making
Compliance Engagement Management:
- Lead compliance engagements with external parties, such as auditors, regulators, and certification bodies
- Coordinate and manage the preparation of documentation, evidence, and reports required for compliance audits and assessments
- Perform third-party vendor risk assessments and collaborate with stakeholders to address identified risks
- Support the success of our third-party vendor risk management program by ensuring compliance and reducing vendor-related risks
Team Collaboration and Cybersecurity Initiatives:
- Participate in APAC and EMEA team’s general activities to stay connected and contribute to the overall Security Strategy
- Promote a culture of collaboration, accountability, and continuous growth within the cybersecurity function
Your present skillset
- Experience: Minimum of 5+ years in governance, risk management, and compliance roles within cybersecurity
- Qualifications: Degree in a related field (e.g., Business, Law, Information Security, Risk Management)
- Certifications: Preferred certifications include CISA, CRISC, CISSP
- Technical Knowledge: Strong understanding of risk frameworks such as ISO 27001, NIST, or equivalent
- Audit & Compliance: Familiarity with auditing processes and experience participating in internal and external audits
- Communication Skills: Strong written and verbal communication skills, with the ability to tailor information to different audiences
- Problem-Solving: Strong analytical and problem-solving skills with a detail-oriented mindset
- Collaboration: A positive, collaborative attitude with the ability to work effectively in cross-functional teams
- Self-Motivation: A proactive and organized self-starter capable of handling competing priorities
- Language Proficiency: Fluency in English is required
QRT is an equal opportunity employer. We welcome diversity as essential to our success. QRT empowers employees to work openly and respectfully to achieve collective success. In addition to professional achievement, we are offering initiatives and programs to enable employees achieve a healthy work-life balance.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Audits Automation CISA CISSP Compliance CRISC Governance ISO 27001 NIST Risk assessment Risk management Security strategy Strategy
Perks/benefits: Startup environment
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.